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Foreword 



This Technical Specification (TS) has been produced by ETSI 3rd Generation Partnership Project (3GPP). 

The present document may refer to technical specifications or reports using their 3GPP identities, UMTS identities or 
GSM identities. These should be interpreted as being references to the corresponding ETSI deliverables. 

The cross reference between GSM, UMTS, 3GPP and ETSI identities can be found under 
http://webapp.etsi.org/kev/quervform.asp . 

The 3GPP Confidentiality and Integrity Algorithms f 8 & f9 have been developed through the collaborative efforts of the 
European Telecommunications Standards Institute (ETSI), the Association of Radio Industries and Businesses (ARIB), 
the Telecommunications Technology Association (TTA), the Tl Committee. 

The f8 & f9 Algorithms Specifications may be used only for the development and operation of 3G Mobile 
Communications and services. Every Beneficiary must sign a Restricted Usage Undertaking with the Custodian and 
demonstrate that he fulfils the approval criteria specified in the Restricted Usage Undertaking. 

Furthermore, Mitsubishi Electric Corporation holds essential patents on the Algorithms. The Beneficiary must get a 
separate IPR License Agreement from Mitsubishi Electronic Corporation Japan. 

For details of licensing procedures, contact ETSI, ARIB, TTA or Tl. 

The contents of the present document are subject to continuing work within the TSG and may change following formal 
TSG approval. Should the TSG modify the contents of the present document, it will be re-released by the TSG with an 
identifying change of release date and an increase in version number as follows: 

Version x.y.z 

where: 

X the first digit: 

1 presented to TSG for information; 

2 presented to TSG for approval; 

3 or greater indicates TSG approved document under change control. 

y the second digit is incremented for all changes of substance, i.e. technical enhancements, corrections, 
updates, etc. 

z the third digit is incremented when editorial only changes have been incorporated in the document. 



Introduction 



This specification has been prepared by the 3GPP Task Force, and gives black-box test data for the algorithm set. The 
test data has been selected to give a high degree of confidence that the implementation is correct. However, no claim is 
made that conformance with this test data guarantees a correct implementation. 

This document is the last of four, which between them form the entire specification of the 3GPP Confidentiality and 
Integrity Algorithms: 

3GPP TS 35.201: "3rd Generation Partnership Project; Technical Specification Group Services and System 
Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity Algorithms; Document 1:^8 and 
j9 Specification". 

3GPP TS 35.202: "3rd Generation Partnership Project; Technical Specification Group Services and System 
Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity Algorithms; Document 2: 
KASUMI Specification". 

3GPP TS 35.203: "3rd Generation Partnership Project; Technical Specification Group Services and System 
Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity Algorithms; Document 3: 
Implementors" Test Data". 
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- 3GPP TS 35.204: "3rd Generation Partnership Project; Technical Specification Group Services and 
System Aspects; 3G Security; Specification of the 3GPP ConfidentiaUty and Integrity Algorithms; 
Document 4: Design Conformance Test Data". 

This document is purely informative. The normative part of the specification of the/5 (confidentiality) and the/9 
(integrity) algorithms is in the main body of Document 1 . The normative part of the specification of KASUMI is found 
in document 2. 
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Scope 



This specification gives black-box test data for the algorithm set. The test data has been selected to give a high degree 
of confidence that the implementation is correct. However, no claim is made that conformance with this test data 
guarantees a correct implementation. 



1 Outline of the design conformance test data 

Section 2 introduces the algorithms and describes the notation used in the subsequent sections. 
Section 3 provides test data for the Confidentiality Algorithm/5. 
Section 4 provides test data for the Integrity Algorithm/9. 



1.1 References 

The following documents contain provisions which, through reference in this text, constitute provisions of the present 
document. 

• References are either specific (identified by date of publication, edition number, version number, etc.) or 
non-specific. 

• For a specific reference, subsequent revisions do not apply. 

• For a non-specific reference, the latest version applies. In the case of a reference to a 3GPP document (including 
a GSM document), a non-specific reference implicitly refers to the latest version of that document in the same 
Release as the present document. 

[1] 3GPP TS 33.102 version 3.2.0: "3rd Generation Partnership Project; Technical Specification 

Group Services and System Aspects; 3G Security; Security Architecture". 

[2] 3GPP TS 33.105 version 3.1.0: "3rd Generation Partnership Project; Technical Specification 

Group Services and System Aspects; 3G Security; Cryptographic Algorithm Requirements". 

[3] 3GPP TS 35.201: "3rd Generation Partnership Project; Technical Specification Group Services 

and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity 
Algorithms; Document 1: f8 and f9 Specification". 

[4] 3GPP TS 35.202: "3rd Generation Partnership Project; Technical Specification Group Services 

and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity 
Algorithms; Document 2: KASUMI Specification". 

[5] 3GPP TS 35.203: "3rd Generation Partnership Project; Technical Specification Group Services 

and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity 
Algorithms; Document 3: Implementors" Test Data". 

[6] 3GPP TS 35.204: "3rd Generation Partnership Project; Technical Specification Group Services 

and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity 
Algorithms; Document 4: Design Conformance Test Data". 

[7] ISO/IEC 9797-1 : 1999: "Information technology - Security techniques - Message Authentication 

Codes (MACs)". 
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Introductory information 



2.1 Introduction 

Within the security architecture of the 3GPP system there are two standardised algorithms; a confidentiaUty algorithm 
f8, and an integrity algorithm /9. These algorithms are specified in a companion document [3]. 

This document provides sets of input/output test data for "black box" testing of physical realisations of the/5 and/9 
algorithms. 

2.2 Radix 

Unless stated otherwise, all test data values presented in this document are in hexadecimal. 

2.3 Bit/Byte ordering 

All data variables in this specification are presented with the most significant bit (or byte) on the left hand side and the 
least significant bit (or byte) on the right hand side. 

2.4 Presentation of input/output data 

The basic data processed by the/S and/9 algorithms are bit streams. In general in this document the data is presented 
in hexadecimal format as bytes, thus the last byte shown as part of an input or output data stream may include between 
and 7 bits that are ignored once the LENGTH parameter is taken into account. (The least significant bits of the byte 
are ignored). 

2.5 Coverage 

For each of the algorithms the test data have been selected such that, provided the entire set of tests is run: 

Each key bit will have been in both the "1" and the "0" states. 

- Each bit of the initialisation fields (COUNT, FRESH, BEARER, DIRECTION) will have been in both the " 1 " 
and the "0" states. 

Every entry in the internal S -boxes will have been used. 



3 Confidentiality algorithm f8 

3.1 Overview 

The test data sets presented here are for the/S confidentiality algorithm. 

3.2 Format 

Each test set shows the various inputs to the algorithm including the plain text data stream to be encrypted/decrypted. 
(The length field is in decimal). 

The fields are: 

Key =CK[0]...CK[127] 

Count = COUNT[0] . . . COUNT[3 1 ] 
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Bearer = BEARER[0] . . .BEARER[3] 

Direction = DIRECTION[0] 

Length = Length of data in decimal 

Plaintext = PT[0] PT[1] PT[Length-l] 

This is followed by the modified input data, i.e. it is the bit-wise exclusive-or of the corresponding keystream and the 
input data to the algorithm. 

Ciphertext = CT[0] CT[l]....CT[Length-l] 

As this is a stream cipher it is purely a matter of context whether the operation is regarded as 'encryption' or 
'decryption'. For the purposes of this document we regard the input as Plaintext and the output as Ciphertext. 

The first test set is shown twice, once in binary format, once in hexadecimal format. This is to explicitly show the 
relationship between the binary data and the hexadecimal presentation. 

The remainder of the test sets are presented in hexadecimal format only. 

3.3 Test Set 1 

3.3.1 Binary Representation 

Key= 1101001111000101110101011001001000110010011111111011000100011100 
0100000000110101110001100110100000001010111110001100011011010001 

Count = 00111001100010100101100110110100 

Bearer = 10101 

Direction = 1 

Length = 253 bits 

Plaintext : 

1001100000011011101001101000001001001100000110111111101100011010 

1011010010000101010001110010000000101001101101110001110110000000 

1000110011100011001111100010110011000011110000001011010111111100 

0001111100111101111010001010011011011100011001101011000111110 

ciphertext : 

1100101000001010011000001011010000101001100111100110100101010100 

1101101111110111011010000110111001000110111101000100000110010000 

1101110010000001101100000111010000000100010010000001001110110101 

0000101010110001111111100100011001011001011110111010001100111 

3.3.2 Hexadecimal Representation 

Key = D3C5D592327FB11C4035C6680AF8C6D1 

Count = 3 98A59B4 

Bearer = 15 

Direction = 1 

Length = 253 bits 

Plaintext : 

981BA6824C1BFB1A B485472 029B71D8 8CE33E2CC3C0B5FC 1F3DE8A6DC66B1F0 

Ciphertext : 

CA0A60B4299E6954 DBF7686E46F44190 DC81B074 044813B5 0AB1FE46597BA338 



£75/ 



3GPP TS 35.204 version 9.0.0 Release 9 



ETSI TS 135 204 V9.0.0 (2010-02) 



3.4 



Test Set 2 



2BD64 5 9F82C44 0E0 952C4 9104 8 5FF4 8 

C675A64B 

OC 

1 

798 bits 



Key 

Count 

Bearer 

Direction 

Length 

Plaintext : 

7ECS12 72 74 3BF161 4 72 644 6A6C3 8CED1 

922B0 34 5 0D3A9975 E5BD2EA0EB5 5AD8E 

59B7BDFD39BEF4B2 484583D5AFE082AE E638BF5FD5A6 0619 

9B134880 



66F6CA76EB543004 
1B199E3EC4316020 



4286346CEF130F92 
E9A1B285E7627953 
3 9 lAO 8 F4AB4 lAAB 



Cipher text : 

1061793DAAACBE40 C9431E292B7FF494 96DB0D31CE24710C 01ACFF1B2C441FA9 
3BB3BD65DE18027A 14CCA571A42E8B12 74AE3 0AC411AB6AF D88F924E65F9812D 
FA8 0EF8E9A7EA753 391D09F480D9147C B39C23A1ACB9AC9B 2A6B4709F7E6DD84 
D8FA5 9A4 



3.5 



Test Set 3 



Key 

Count 

Bearer 

Direction 

Length 

Plaintext : 

FD40A41D370A1FS5 745 095687D47BA1D 3SD2349E23F64439 2C8EA9C49D4 0C132 

71AFF264D0F248 



0A8B6BD8D9B0 8B0 8D64E32D1817777FB 

544D49CD 

04 



310 bits 



Cipher text : 

22B707A481F264BE 6 91994C2A2 01354D 5741A2ESB4S24EE9 DF3 0D8D945351S5B 

D439223EBBD074 



3.6 



Test Set 4 



Key = AA1F95AEA533BCB32EB63BF52D8F831A 

Count = 72D8CS71 

Bearer = 10 

Direction = 1 

Length = 1022 bits 

Plaintext : 

FB1B96C5C8BADFB2 E8E8EDFDE78E57F2 AD81E74103FC43 OA 534DCC37AFCEC70E 

1517BB06F27219DA E49022DDC47A068D E4C9496A951A6B09 EDBDC864C7ADBD74 

0AC50C022F3082BA FD22D78197C5D508 B977BCA13F32E652 E74BA728576077CE 

628C535E87DC6077 BA07D29068590C8C B5F1088E082CFA0E C9613 02D69CF3D44 



Ciphertext : 

5C6FD2D34BE8B0F5 2126 0BD758881F7 6C4F11A5C3D42 028 A9A029F2E063 0454 

829AA0A69D58D023 02E8DB3D6E9FF350 09B3595984BEB400 31271BF78727270B 

9608520036125ADS 8A28213513CBA08C 7BB9EA966C0713FD 2DFFE2BADC6287CF 

79B244B7236124FB 51B863684C4D89D1 94 0541D3568 9022 12 081FE6 94DC4594 
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3.7 



Test Set 5 



9618AE4S8 91F86 578EEBE9 0EF7A12 02E 

C675A64B 

OC 



1245 bits 



Key 

Count 

Bearer 

Direction 

Length 

Plaintext : 

8DAA17B1AE050529 C6827F28C0EF6A12 42E93F8B314FB18A 77F790AE049FEDD6 

12267FECAEFC4501 74D76D9F9AA7755A 30CD90A9A5874BF4 8EAF70EEA3A62A25 

0A8B6BD8D9B08B08 D64E32D1817777FB 544D49CD4972 0E21 9DBF8BBED33904E1 

FD40A41D370A1F65 745 095687D47BA1D 36D2349E23F64439 2C8EA9C49D4 0C132 

71AFF264D0F24841 D6465F0996FF84E6 5FC517C53EFC3363 C38492A8 



Ciphertext : 

AAF8E8B349FBABB9 5CS21DE6FB516744 6054AE7CFA946F99 SC2S 05345A1A2AF 

44EEA688B759FFE3 E22D6E17BD9E7079 CC54E8D492DBFDE7 9E84 043849821A24 

7A67D3509BA16B49 15FDDDD638E252F4 371E471D1B39B415 8B47F14D037BBD28 

37804134AD493BFC 14 0E437F5EBF9C29 D5D8A5816F926AA2 76E9A743A62141AD 

EB653BD2963C9F54 1F5E1334B77592B1 ADED4436722828 01 32A747D8 



3.8 



Test Set 6 



Key = 54F4 
Count = ACA4 
Bearer = OB 
Direction = 
Length = 2837 
Plaintext : 
40981BA6824C1BFB 
1AB485472029B71D 
808CE33E2CCCBFC6 
FA16BB11ADAE24 8 8 
762DD0C2C9CD68D4 
CABE7D9F8 98A411B 
5E4CEC034C73E605 
CD8C87202364B8A6 
9FE4189F15420026 
5ABE6 52 72AF6 7AD 
888138616B681262 
B09550 

Ciphertext : 

BFB39672186E62B7 

679207F035194553 

8566B0F646394892 

408FCA9EC4A38869 

19590CA8D25F9AFD 

B1B7F194 5AEA8 3FA 

6AFA95A3E9DB5C4 7 

69576AA958CE5909 

48E7BAE30D5BB21D 

B6D7530E3B85FA63 

A41F43ABEFD4 8D7 

2261B0 



E2E04C83786EEC8FB5ABE8E3S5S6 
F50F 



bits 

4286B299783DAF44 
36BD1A3D90DC3A41 
34E1B259060876A0 
79FE52DB2543E53C 
496A792508614014 
FDB84F68F6727B14 
B4 310EAAADCFD5B0 
87954CB05A8D4E2D 
FE4CD12104932FB3 
A1BE65A6B4C9C069 
F954D0E771174878 



7FB3 9F92 78A8AEA6 
DDF973E830C3E249 
D443F394DA13DAC2 
1C513CFED22357B2 
5BB00FB081EAD4BD 
C3B2208281B30883 
3CD054D2E0A7F080 
3ACB8A5F72 96A7F 
CABD217CB5 5B8 99F 
1C65C3402A87D98F 
CCC9C21DDF02792B 



2C099F7AB0F58D5C 
B46D51672AC4C966 
FBB5A437EBCC8D31 
F445D3D828CE0BF5 
B13B6AA51128C18C 
99CDD30DF0443AB4 
CA2 7FFD8 9D144DF4 
99E73DB160DEB180 
8F735340438AAF7E 
3234092C4D018F17 
0D92291D86299972 



0468E05A2BB57E8B 
4EF6C9449FDC0735 
05D84B2628191A0C 
F7742FB8D5CE550E 
A0FAC5DC78F79771 
E590196D6499B431 
CB5967C709DE78EC 
E671C3717B1B514A 
A7D8EA0557F672E4 
3B6FB971FCCB1AF1 
8EE8A77988CDC317 



8E46B104F08F01B4 
3A2BE0 6 3DA4BC8D2 
C19E4454318745E3 
C560593D97278A59 
D6A90B87978C2FF1 
A66653330BCBA110 
792759427C9CC1F8 
AD0841E96741A5D5 
CA6FD5CFD3A195CE 
56C6DB9DC8A6D80B 
DB741CFA4F37B8B5 



SD6AA1B05AE83147 
1F8B453EEE70001D 
574E974507A9A9F3 
03CAA9CFFFF54100 
8B6AE21BF9D0C443 
7EA97E080830C204 
8435CAE9B3617655 
0AE7D7792E44F17C 
36BE18350D58CS5F 
A6592DF2CCFE6893 
1046C515401ABB13 



4 Integrity algorithm f9 

4.1 Overview 

The test data sets presented here are for the/9 integrity algorithm. 

Each test set shows the various inputs to the algorithm including the plain text data stream to be "MAC'd. The length 
field is in decimal. 

The fields are: 

Key = IK[0]...IK[127] 
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Count = COUNT-I[0]...COUNT-I[31] 

Fresh = FRESH[0]...FRESH[31] 

Direction = DIRECTION[0] 

Length = Length of data in decimal 

Message = MESSAGE[0]...MESSAGE[Length-l] 

This is followed by the calculated value for MAC-I. 

Output =MAC-I[0]...MAC-I[31] 

The first test set is shown twice, once in binary format, once in hexadecimal format. This is to explicitly show the 
relationship between the binary data and the hexadecimal presentation. 

The remainder of the test sets are presented in hexadecimal format only. 

4.2 Test Set 1 

4.2.1 Binary Representation 

Key= 0010101111010110010001011001111110000010110001011011001100000000 
1001010100101100010010010001000001001000100000011111111101001000 

Count = 00111000101001101111000001010110 

Fresh = 10111000101011101111110110101001 

Direction = 

Length = 88 bits 

Message : 

0011001100110010001101000110001001100011001110010011100001100001 

001101110011010001111001 

Output: 01000110111000000000110101001011 

4.2.2 Hexadecimal Representation 

Key = 2BD6459F82C5B300952C49104881FF48 

Count = 38A6F056 

Fresh = B8AEFDA9 

Direction = 

Length = 88 bits 

Message : 

333234S263393861 373479 

Output: 46E00D4B 

4.3 Test Set 2 

Key = 7E5E94431E11D73828D739CC6CED4573 

Count = 36AFS144 

Fresh = 9838F03A 

Direction = 1 

Length = 254 bits 

Message : 

B3D3C9170A4E1632 F6 0F861013D22D84 B726B6A278D802D1 EEAF1321BA5929DC 

Output : 2BEEF3AC 
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4.4 



Test Set 3 



Key 

Count 

Fresh 

Direction 

Length 

Message : 

BBB057038809496B CFF86D6FBC8CE5B1 35A06B166 054F2D5 65BE8ACE75DC851E 

0BCDD8F07141C495 872FB5D8C0C66A8B 6DA556663E4E4612 05D8458 0BEE5BC7E 



D3419BE821087ACD02123A9248 033359 

C7590EA9 

57D5DF7D 



511 bits 



Output: 02158170 



4.5 



Test Set 4 



Key 

Count 

Fresh 

Direction 

Length 

Message : 

35C68716633C66FB 750C2668S5D53C11 EA05B1E9FA49C839 8D48E1EFA5909D39 

47902837F5AE96D5 A05BC8D61CA8DBEF 1B13A4B4ABFE4FB1 06 045B674BB5472 

9304C382BE53A5AF 05556176F6EAA2EF 1D05E4B083181EE6 74CDA5A485F74D7A 



83FD23A244A74CF358DA3 019F1722S35 

36AF6144 

4F302AD2 

1 

768 bits 



Output: 95AE41BA 



4.6 



Test Set 5 



Key 

Count 

Fresh 

Direction 

Length 

Message : 

D3C5383962682071 7765667620323837 636240981BA6824C 1BFB1AB485472029 

B71D8 8CE3 3E2CC3 C0B5FC1F3DE8A6DC 



6 8 32A6 5CFF44 73 621EBDD4BA2 6A921FE 

36AF6144 

9838F03A 



383 bits 



Output: 8B2D570F 



4.7 Test Set 6 



5D0A8 0D8134AE196 77824B671E838AF4 

7827FAB2 

A56C6CA2 

1 

2558 bits 



Key 

Count 

Fresh 

Direction 

Length 

Message : 

70DEDF2DC42C5CBD 3A96F8A0B11418B3 

15 3BE2D3C0 6DFDB2 D16E9C3 5 715 8BE6A 

D5 8 95 3 73 0FF3 0C9E C4 7 0FFCD6 6 3DC342 

3731F8B4BAA8D1A8 9C06E81199A97162 

C3 99993FC773 94F9 E0 972 0A8118 5 0EF2 

012A0 0BB413B9CB8 18 8A7 3CD6BAE31C 

7C9EF8DEC0 94E5 3 3 76 34 78D5 8D2C5F5 

E62CE74 7E991E3 7EA82 3FA0FB2192 3 

1A9C73 0C52FF72D9 D3 8EEDBAB21FDE1 

A15464EAA733385D BBEB6FD735 09B857 



608D5733604A2CD3 
41D6B861E491DB3F 
01C36ADDC0111C35 
27BE344EFCB436DD 
3B2EE05D9E617360 
C67B34B1B00019E6 
B827A0148C5948A9 
B79905B733B631E6 
43A0EA17E23EDC1F 
E6A419DCA1D8 9 7A 



6AABC70CE3193BB5 
BFEB518EFCF048D7 
B3 8AFEE7CFDB582E 
D0F096C064C3B5E2 
9D86E1C0C18EA51A 
A2B2A690F02671FE 
6931ACF84F465A64 
C7D6860A3831AC35 
74CBB3638A2033AA 
F977FBAC4DFA3 5EC 



Output : 3AE4BFF3 
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Annex A (informative): 
Change history 



Change history | 


Date 


TSG# 


TSG Doc. 


CR 


Rev 


Subject/Comment 


Old 


New 


12-1999 


- 






- 


ETSI SAGE Publication (restricted) 




SAGE 
vl.O 


09-2000 


SA_07 








Approved by TSG SA and placed under change control 


SAGE 
vl.O 


3.1.0 


07-2001 


- 






- 


Word version received: Re-formatted into 3GPP TS format (MCC) 
No technical change from version 3.1 .0. 


3.1.0 


3.1.1 


08-2001 










Addition of Mitsubishi IPR information in 

Foreword and correction of reference titles. No technical change 
from version 3.1.0. 


3.1.1 


3.1.2 


08-2001 


- 






- 


Release 4 version created. 


3.1.2 


4.0.0 


06-2002 


- 






- 


Release 5 version created. 


4.0.0 


5.0.0 


12-2004 


- 


- 


- 


- 


Release 6 version created. 


5.0.0 


6.0.0 


06-2007 


- 


- 


- 


- 


Release 7 version created. 


6.0.0 


7.0.0 


12-2008 


- 


- 


- 


- 


Release 8 version created 


7.0.0 


8.0.0 


2009-12 


- 




- 


- 


Release 9 version created. 


8.0.0 


9.0.0 
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